In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfaces_assign.php, which can result in stored cross-site scripting. The attacker must be authenticated with at-least "Interfaces: PPPs: Edit" permission. This vulnerability has been addressed by the vendor in the product release notes as "ui: legacy_html_escape_form_data() was not escaping keys only data elements."
Security readout for executives and security teams
Plain-English summary
An authenticated OPNsense user with PPP edit rights could store malicious HTML/script content through a point-to-point interface identifier. That content may run when another user opens the interface assignment page. This is a medium-risk admin-console issue: impact depends on who has delegated PPP permissions and who later views the affected page.
Executive priority
Treat this as a scheduled but real remediation item. Prioritize faster where OPNsense administration is delegated to multiple teams, contractors, or managed service accounts, because compromise may affect administrator browser sessions and console trust.
Technical view
CVE-2025-34182 is stored XSS in Deciso OPNsense before 25.7.4. The ptpid parameter in /interfaces_ppps_edit.php was not sanitized for HTML-related characters and was rendered in /interfaces_assign.php. Vendor notes describe the fix as correcting legacy_html_escape_form_data() so keys, not only data elements, are escaped.
Likely exposure
Exposure is likely limited to OPNsense deployments before 25.7.4 where non-fully-trusted accounts have Interfaces: PPPs: Edit permission. Systems without delegated PPP editing are less exposed, but still should update because privileged console users can be targeted.
Exploitation context
The provided sources do not show KEV listing or active exploitation. Exploitation requires authenticated access with at least Interfaces: PPPs: Edit permission and user interaction when another user visits the affected assignment page.
Researcher notes
Evidence supports stored XSS, not unauthenticated compromise. The public bundle names the vulnerable parameter and affected pages, but does not provide exploitation telemetry. Keep validation focused on version, permissions, and configuration review rather than offensive reproduction.
Mitigation direction
Upgrade OPNsense to 25.7.4 or later.
Review vendor release notes for the exact fixed release guidance.
Limit Interfaces: PPPs: Edit permission to trusted administrators.
Audit delegated administrator accounts and remove unnecessary PPP edit rights.
Review PPP entries for unexpected or untrusted identifiers.
Validation and detection
Inventory OPNsense systems and confirm their installed version.
Flag any OPNsense instance older than 25.7.4.
Review accounts or groups with Interfaces: PPPs: Edit permission.
Check PPP configuration entries for unexpected HTML-like content.
Confirm vendor release notes are reflected in change records.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.